Defending your network with a firewall should be common sense for most businesses, especially after the many security breaches of 2014. Actually picking that firewall is much easier said than done, though, since there is a huge range of options out there. Firewall sizing depends on several factors, such as the amount of traffic the firewall will see and the features you actually need.
Features That Define a Modern Firewall
Features are a big part of what makes a firewall useful today. Many advanced Next-Generation Firewalls (NGFW) include application control, intrusion prevention, and content filtering, which can dramatically improve an admin’s ability to control a network. These useful services are usually tied to a subscription, though, so it does not always make sense to pay for features you will not use. How much you need these advanced features depends on your use case. If you are running a firewall in a home office where you are the only user, content filtering probably will not do much for you. Most cases still get real benefit from these features, so it is worth discussing your specific use case with your provider to figure out what you actually need. That said, almost every firewall manufacturer requires a subscription for antivirus signature updates, so make sure you are at least covering that.
User Count and Firewall Sizing
Firewall sizing gets trickier once you move past features and the basic job of the firewall. Manufacturers usually size firewalls by throughput, user count, or both. User count means the total number of devices, including BYOD devices, accessing the firewall at any given time, not the average number of users, and that distinction can create some real surprises in what you actually need. A common mistake is using employee count to size a firewall meant to serve Wi-Fi to customers. That can leave a firewall built for a handful of users getting hit with hundreds, causing patchy performance at best and a total overload at worst. For internet-facing servers, concurrent user count is the average number of users on an application or website at once, and if a company expects 100 average users but hits 1,000 at some point, performance will suffer or fail outright, since the firewall simply cannot process that volume. For all practical purposes, that looks just like a DDoS attack.
Throughput and Firewall Sizing
Throughput also factors into firewall sizing, since it determines how fast traffic actually moves through the device. Most firewalls list a speed rating in their technical specs. They cannot make your internet connection magically faster, but they can absolutely become a bottleneck. If you have a 100 Mbps connection and choose a firewall rated for 25 Mbps throughput, the firewall will slow your internet down significantly, since it simply cannot process traffic at 100 Mbps.
A Real-World Firewall Sizing Example
Let’s look at a real example. The Fortinet FortiGate-100D is rated for 300 Mbps of internet throughput while running proxy-based antivirus, with a recommended user count of up to 150. Run a 1 Gbps connection through that FortiGate, and it will slow to about 300 Mbps once antivirus services kick in, since those services use up some of the firewall’s processing power. That same firewall can handle 1.5 Gbps with no services running, but that is not a great idea either, since it means the firewall is not protecting much. On the other side, if 200-plus users hit that firewall at once, speeds drop too, since the device gets taxed by sheer traffic volume. Firewall sizing is a balancing act, and getting it right takes weighing all of these factors together for your specific environment.
There is a lot more to actually administering a firewall than we have covered today (NAT, VPN management, rules, and more), but this is a solid place to start when buying a new firewall or upgrading an existing one. Vault Networks can help you manage the more advanced elements of your firewall, and we can also help procure the hardware itself, thanks to our relationships with several firewall manufacturers. To learn more about implementing a firewall in your environment, or for questions about firewall sizing for your business, reach out to us at (305) 735-8098 option 2 or by emailing sales@vaultnetworks.com.